CVE-2021-37388

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
06/08/2021
Last modified:
13/08/2021

Description

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-615_firmware:3.03ww:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-615:c2:*:*:*:*:*:*:*